1. Overview
We process personal data under the EU General Data Protection Regulation (GDPR) and Estonian law. Using the Platform is governed by our Terms of Service and Acceptable Use Policy; this Policy is incorporated in both. Actual Armor is one direction of Actual Armor Group; every direction runs on the same platform under the same operating entity and the same privacy model, so the Policy you read on another direction’s site is this Policy with that direction’s domains and contacts.
2. Who is the controller
Tuluko Group OÜ, Estonian Commercial Register code 14335661, registered at Tuukri tn 19-315, 10120 Tallinn, Estonia, is the controller for the processing described in Section 3 as ours. Contact for privacy matters: privacy@actualarmor.com.
3. When we are the controller, when you are
The Platform is infrastructure: you decide what to investigate, what material to upload, which sources and connectors to switch on, whom to share a result with. That decides the roles.
| Data | Who decides why and how | Our role |
|---|---|---|
| Your account, billing, support, product analytics, cookies on our sites | We do | Controller |
| Content you bring in or the Platform gathers on your instruction: uploaded files, prompts, the subjects of an investigation, connector output, results, shares | You (or your organisation) | Processor on your instructions |
| Core solutions delivered by our back-office on your order | You (the client) | Processor; the order itself is our controller data |
| On-premise deployments | The client entirely | Neither — the data never reaches us |
Where you are the controller, you are responsible for the lawful basis, for the purpose, for the rights of the people concerned and for honouring their requests; we act on your documented instructions (these documents and your use of the product), keep the data confidential, apply the security in Section 14, use only the sub-processors in Section 9, and delete or return the data as Section 11 describes. A data processing agreement covering this is available on request and is signed for Core, white-label and enterprise engagements.
4. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | E-mail address, name (optional), account ID, sign-in identity (for example your Google account identifier when you sign in with Google), organisation, language, time zone, consent records. | You, at sign-up and in settings. |
| Billing data | Credit balance and ledger, transaction IDs, invoices, billing address, VAT number where applicable, Core orders and deductions. Card details are held by Stripe; we never see the full card. | You; Stripe. |
| Run metadata | Which solution, agent, workflow or schedule ran, when, from where (app, API, MCP endpoint, schedule, shared asset), which model providers and connectors it used, how many credits it consumed, errors. | Generated by the Platform. |
| Your content and results | Files, text, URLs, subjects you enter, prompts, knowledge bases, what connectors return, the results a run produces, and the assets you build (agents, workflows, MCP configurations, chats). You are the controller of the personal data in it. | You; sources and connectors you switch on. |
| Artifact and sharing activity | The identifier of each artifact and chat export, its Private or Public state and every change to it, downloads and openings of Public artifacts by other signed-in users (their account ID and time), which agents, workflows and MCP configurations you shared and who ran them; each entry with the acting account and timestamp. | Generated when you create, change, share or open artifacts. |
| Usage and device data | Feature interactions, pages viewed, browser and device type, IP address (city-level location), timestamps, referrer. | Collected automatically; see Cookies. |
| Support data | Messages, attachments and metadata when you contact us. | You. |
| Data-subject requests | Requests from people who appear in a user’s result, and the record of how we handled them. | The person concerned. |
Do not upload special-category data (health, biometrics, sexual orientation, religion, political opinion, union membership, criminal history) about identified people unless the law permits it and you have the safeguards it requires. Do not use real people’s data to test assets when synthetic data would do.
5. Purposes and legal bases
| Purpose | What it covers | Legal basis |
|---|---|---|
| Provide and operate the Platform | Account, authentication, credit balance, running solutions, agents, workflows, schedules, API and MCP access, connectors, sharing, Core orders and their delivery. | Contract (GDPR Art. 6(1)(b)). |
| Process your content on your instruction | Everything in the “your content and results” row. | Your instruction as controller; we act as processor (Art. 28). |
| Billing and tax | Payments, ledger, invoices, VAT, refunds, disputes. | Contract; legal obligation (Art. 6(1)(c), Estonian accounting and tax law). |
| Secure, debug and improve the Platform | Abuse and fraud prevention, enforcement of the Acceptable Use Policy, error tracking, product analytics on usage events (never on your content), quality of solutions. | Legitimate interests (Art. 6(1)(f)). |
| Service communications | Deduction notices, delivery of Core results, security and legal notices, replies to your requests. | Contract; legitimate interests. |
| Marketing | Product news, offers, newsletters. | Consent (Art. 6(1)(a)), given separately from accepting the Terms; withdrawable at any time. |
| Handle requests from people in results | Section 7. | Legal obligation; legitimate interests. |
| Comply with law and defend claims | Court orders, regulatory requests, legal holds, disputes. | Legal obligation; legitimate interests. |
6. Sources the Platform reads on your instruction
A run reads only the sources and connectors it is allowed to and that you switched on. By category: the public web (search and retrieval of pages you point at or that a solution finds); social-platform connectors (for example LinkedIn and YouTube) that return what a profile, company or channel makes public; official and open registries (company registers, legal-entity identifiers, securities filings); legal and court corpora in the countries the Platform covers; third-party data services; and MCP servers you connect yourself. We do not read closed databases, log-in-walled content or private communications, and the Platform does not offer people-enrichment or contact-extraction tools.
Court and legal registries are personal data whenever a natural person is the subject. Lookups by company run as ordinary runs; a lookup by a private individual’s name passes through a human gate. Coverage of every source is partial and dated; a result states the date of its sources, and an absence of signals is never a clearance. The list of sources changes by country and over time; the current set is shown in the application.
Artifacts generated as HTML pages may load fonts, scripts or images from third-party servers when opened; those servers receive the viewer’s request, including the IP address. We render artifacts in an isolated context and do not add trackers of our own to them.
7. If you appear in someone’s result
If you believe a user of the Platform has processed data about you, write to privacy@actualarmor.com. The user who ran the investigation is the controller of that data; we are the processor. We will forward your request to that user, tell you we did, keep a record of the request, and act ourselves where the law obliges us to — for example where the processing breaches our Acceptable Use Policy, where the user cannot be reached, or where a court or supervisory authority requires it. We never disclose one user’s identity to another person without a legal basis.
If someone has sent you a result about yourself — with or without a demand attached — send us the result identifier printed on it. We will tell you whether it was produced on the Platform, when, whether it has been altered, and which parts came from public sources and which from material the sender supplied. Using a result to extort, intimidate or defame is a breach of our Acceptable Use Policy; we suspend such accounts, preserve the evidence and cooperate with law enforcement.
8. AI model providers
Runs use large language models from several providers, currently including OpenAI, Google, Anthropic and xAI, chosen per solution. Your prompts, content and results are sent to the provider a run uses, under terms that require the provider to process them only to return the response, not to train its models on them, and to delete them after a short retention period used for abuse monitoring. We do not train our own models on your content or results. Our own multi-agent systems run on our infrastructure. Where a provider changes its terms in a way that affects this, we update this Policy before using it.
9. Who we share data with
We share personal data only with sub-processors who help us run the Platform, under contracts that bind them to our instructions, to confidentiality and to GDPR-level safeguards; with people you share with; and with authorities where the law requires.
| Category | Named providers | What they process |
|---|---|---|
| Hosting, storage, CDN and security | Cloud infrastructure providers in the EU and US; Cloudflare | Everything the Platform stores and serves; request logs |
| AI model inference | OpenAI, Google, Anthropic, xAI, and others as added | Prompts, content and results of a run (Section 8) |
| Connectors and data sources | Social-platform, registry and data-service connectors, including actors hosted on Apify and equivalent platforms | The queries a run sends and the public data returned |
| Payments | Stripe | Payment and billing data |
| Product and web analytics | PostHog, Google Tag Manager, Google Analytics | Usage and device data; never prompts, content, results or e-mail addresses |
| E-mail delivery and support | SendPulse; our helpdesk tooling | E-mail address, service and marketing messages, support data |
| Sign-in | Your Google identity when you sign in with it |
The full current list, with locations and transfer mechanisms, is available on request and is attached to every data processing agreement. We may also disclose data to comply with law, to enforce our Terms and Acceptable Use Policy, to protect users or the public, and in a merger, acquisition or sale of assets, with the safeguards this Policy requires carried over.
10. International transfers
Some sub-processors process data outside the EEA, chiefly in the United States. We rely on European Commission adequacy decisions (including the EU–US Data Privacy Framework where the provider is certified) and on Standard Contractual Clauses with supplementary measures where needed. Connectors return public data from the country of the source.
11. Retention and deletion
You control the life of what you build. Deletion is self-service in the application, at three levels: an object (a result, chat, agent, workflow, MCP configuration or schedule), all your content, or your account. An object or your content is removed immediately and purged from backups within 30 days; its Public link and any chat export link stop working at once. Deleting your account offers an export first, starts a 14-day grace period in which you can cancel, then erases the account, all objects, shares and connector tokens, with backups purged within a further 30 days.
| Data | Retained | Why |
|---|---|---|
| Account data | Life of the account, plus the grace period | Contract |
| Your content, results, assets, shares | Until you delete them or the account; 30 days in backups | Your instruction |
| Credit ledger, invoices, payment records, Core orders | 7 years after the transaction | Estonian Accounting Act and tax law |
| Security and access logs | Up to 12 months | Security |
| Run metadata (what ran, when, what it consumed — not the content) | 24 months | Billing disputes, abuse investigation |
| Artifact and sharing activity record | 24 months (openings by other users: 12 months) | Verification, disputes, accountability for sharing |
| Support correspondence | 24 months after the case closes | Legitimate interests |
| Product analytics events | 24 months | Legitimate interests |
| Marketing consent and unsubscribe records | Until withdrawal, plus 3 years as proof | Legal obligation |
| Data under a legal hold | For the duration of the hold | Legal obligation |
Core deliverables are kept by our back-office only for the duration of the engagement and the retention period its order states. On-premise deployments hold their own data; we retain nothing from them. Aggregated or anonymised statistics may be kept indefinitely.
12. Your rights
For data we control you may access it, correct it, have it erased, restrict or object to its processing, take it with you in a portable format, and withdraw any consent, all subject to the limits the law sets. Export and deletion are available in the application; anything else, write to privacy@actualarmor.com. We answer within one month and may need to verify your identity. You can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live. For data a user controls, see Section 7.
13. Marketing and communications
Service messages — deduction notices, Core deliveries, security and legal notices, replies — are part of the Platform and cannot be opted out of while you have an account. Marketing messages are sent only if you opted in, separately from accepting the Terms; every one has an unsubscribe link, and you can also change the setting in the application. We do not sell or rent personal data.
14. Security
Encryption in transit and at rest, access on a least-privilege basis with logging, tenant isolation between accounts, secrets kept out of prompts and analytics, human gates on sensitive lookups, abuse monitoring and rate limits, regular reviews. Product analytics never receives prompts, content, results or e-mail addresses. No system is perfectly secure; if a breach affects you we notify you and the supervisory authority as the law requires.
15. Cookies and tracking
We use cookies and similar technologies to run the Platform, measure performance and remember preferences. Non-essential cookies are set only after you consent through the cookie banner, and you can change your choice at any time there or in your browser. The full cookie table is in our Cookie Policy.
| Type | Purpose | Retention |
|---|---|---|
| Strictly necessary | Authentication, security, consent record, basic functions. | Session to 12 months. |
| Functional | Preferences, language, UI settings. | Up to 12 months. |
| Analytics (consent) | Usage and performance measurement. | Up to 24 months. |
| Marketing (consent) | Campaign attribution. | Up to 24 months. |
16. Children
The Platform is for adults and organisations. We do not knowingly collect personal data from anyone under 18; if you believe we have, contact us and we will delete it.
17. Changes to this Policy
We may update this Policy. The new version is posted here with a new “Last updated” date; material changes — a new category of data, a new purpose, a provider that changes how content is handled — are announced in the application or by e-mail before they take effect.
18. Contact
Tuluko Group OÜ
Registry code 14335661
Tuukri tn 19-315, 10120 Tallinn, Estonia
Privacy and data-subject requests: privacy@actualarmor.com
Legal matters: legal@actualarmor.com